9.8

CVE-2025-47867

A Local File Inclusion vulnerability in a Trend Micro Apex Central widget in versions below 8.0.6955 could allow an attacker to include arbitrary files to execute as PHP code and lead to remote code execution on affected installations.

Data is provided by the National Vulnerability Database (NVD)
TrendmicroApex Central Version2019 Update- SwEdition-
   MicrosoftWindows Version-
TrendmicroApex Central Version2019 Updatebuild_3752 SwEdition-
   MicrosoftWindows Version-
TrendmicroApex Central Version2019 Updatebuild_5158 SwEdition-
   MicrosoftWindows Version-
TrendmicroApex Central Version2019 Updatebuild_6016 SwEdition-
   MicrosoftWindows Version-
TrendmicroApex Central Version2019 Updatebuild_6288 SwEdition-
   MicrosoftWindows Version-
TrendmicroApex Central Version2019 Updatebuild_6394 SwEdition-
   MicrosoftWindows Version-
TrendmicroApex Central Version2019 Updatebuild_6481 SwEdition-
   MicrosoftWindows Version-
TrendmicroApex Central Version2019 Updatebuild_6511 SwEdition-
   MicrosoftWindows Version-
TrendmicroApex Central Version2019 Updatebuild_6571 SwEdition-
   MicrosoftWindows Version-
TrendmicroApex Central Version2019 Updatebuild_6658 SwEdition-
   MicrosoftWindows Version-
TrendmicroApex Central Version2019 Updatebuild_6660 SwEdition-
   MicrosoftWindows Version-
TrendmicroApex Central Version2019 Updatebuild_6890 SwEdition-
   MicrosoftWindows Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.52% 0.659
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
security@trendmicro.com 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.